d494eda301
Upgrade npm to latest version in both backend and frontend Dockerfiles to fix the command injection vulnerability in glob's CLI (CVE-2025-64756). The vulnerability exists in npm's bundled glob package (< 10.5.0 or < 11.1.0).